Enrich OpenCTI CVEs with exploits, EPSS, CISA KEV, and affected software from Vulners 200+ sources.
945
On-demand vulnerability enrichment for OpenCTI. When a CVE appears in your instance, Vulners adds the context NVD doesn't provide — exploits, affected software, vendor advisories, EPSS, CISA KEV, and complete CVSS vectors.
Type: Internal Enrichment · Scope: Vulnerability
The connector triggers when a Vulnerability entity is created or manually enriched in OpenCTI. It calls the Vulners API and writes structured STIX 2.1 objects back into your instance.
One connector replaces three. Vulners enrichment includes EPSS scoring, CISA KEV status, and full CVSS vectors — no need for separate connectors for each signal.
CVE enriched by Vulners — data coverage overview showing affected software, exploits, and reports
| Signal | NVD Import Only | + Vulners (Free) | + Vulners (Paid) |
|---|---|---|---|
| CVSS v3 vector | Partial | Full (all fields) | Full |
| EPSS score & percentile | — | Yes | Yes |
| CISA KEV status | — | Yes + first-seen date | Yes |
| Semantic labels | — | Auto-generated | Auto-generated |
| Data coverage overview | — | Counts (e.g. 72 products, 3 exploits, 10 reports) | Counts |
| Affected software | — | Summary count + stub entity | Named products with CPE & versions |
| Exploits & tools | — | Summary count + stub entity | Named exploits with details |
| Reports & analysis | — | Summary count + stub entity | Full report content & titles |
| Cross-CVE software linking | — | — | Pivot from product → all its CVEs |
| Vulners AI Score | — | — | Proprietary risk score |
| CWE classification | — | — | Yes |
Available to all users with a free Vulners API key. No CVE limits, no quotas.
Free enrichment answers the critical prioritization questions: Does an exploit exist? How many products are affected? Is this in CISA KEV? What's the EPSS percentile? The data coverage overview table — showing counts like "72 affected products, 3 exploits, 10 reports" — appears directly in the CVE description.
Stub entities for software, tools, and reports are clean single records reused across all enriched CVEs. No database bloat, no orphaned objects. Each stub carries an upgrade path to full intelligence.
Paid enrichment adds the "which" and "what": named product versions with CPE strings, exploit PoC names, full threat intel reports with titles and dates. Software observables with CPE strings link across CVEs sharing the same affected configuration — pivot from any product to every CVE that hits it.
Bulk import connectors pull every CVE, every exploit, every advisory on a 24-hour cycle. That means 200k+ CVEs loaded whether your team tracks them or not — and their own docs warn this requires clustered OpenCTI infrastructure.
Vulners takes the opposite approach. As an internal enrichment connector, it fires only when a CVE actually appears in your instance. You get deep context on the vulnerabilities that matter to your organization, with a single lightweight container. No cluster required.
| Bulk Import | Vulners Enrichment | |
|---|---|---|
| Architecture | External Import (scheduled) | Internal Enrichment (on-demand) |
| Triggers | Every 24h, pulls everything | When a CVE appears in YOUR data |
| Data volume | All CVEs regardless of relevance | Only what matters to your org |
| Infrastructure | May need clustered deployment | Single container |
services:
vulners-enrichment:
image: vulners/opencti-connector:latest
environment:
- OPENCTI_URL=http://opencti:8080
- OPENCTI_TOKEN=${OPENCTI_ADMIN_TOKEN}
- CONNECTOR_ID=${VULNERS_CONNECTOR_ID} # Generate with: uuidgen
- CONNECTOR_NAME=Vulners Enrichment
- CONNECTOR_TYPE=INTERNAL_ENRICHMENT
- CONNECTOR_SCOPE=Vulnerability
- CONNECTOR_AUTO=true
- CONNECTOR_LOG_LEVEL=info
- VULNERS_API_KEY=${VULNERS_API_KEY}
restart: always
Set CONNECTOR_AUTO=true to enrich every new Vulnerability automatically. Set to false for manual enrichment only.
VULNERS_API_KEY| Variable | Required | Default | Description |
|---|---|---|---|
OPENCTI_URL | Yes | — | OpenCTI platform URL |
OPENCTI_TOKEN | Yes | — | OpenCTI API token |
CONNECTOR_ID | Yes | — | Unique connector UUID (uuidgen) |
CONNECTOR_NAME | No | Vulners Enrichment | Display name in OpenCTI |
CONNECTOR_TYPE | No | INTERNAL_ENRICHMENT | Connector type |
CONNECTOR_SCOPE | No | Vulnerability | Entity types to enrich |
CONNECTOR_AUTO | No | false | Auto-enrich new entities |
CONNECTOR_LOG_LEVEL | No | info | Logging level |
VULNERS_API_KEY | Yes | — | Your Vulners API key |
VULNERS_API_URL | No | https://vulners.com | Vulners API endpoint |
VULNERS_MAX_TLP | No | TLP:AMBER | Maximum TLP marking level |
The connector creates and links these STIX 2.1 objects:
Built by Vulners — vulnerability intelligence from 218+ sources, 235k+ CVEs, 256k+ exploits.
Content type
Image
Digest
sha256:ac33ea4aa…
Size
168.1 MB
Last updated
4 months ago
docker pull vulners/opencti-connector